U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Checklist Repository

The National Checklist Program (NCP), defined by the NIST SP 800-70, is the U.S. government repository of publicly available security checklists (or benchmarks) that provide detailed low level guidance on setting the security configuration of operating systems and applications.

NCP provides metadata and links to checklists of various formats including checklists that conform to the Security Content Automation Protocol (SCAP). SCAP enables validated security products to automatically perform configuration checking using NCP checklists. For more information relating to the NCP please visit the information page or the glossary of terms.
Please note that the current search fields have been adjusted to reflect NIST SP 800-70 Revision 4.

Search for Checklists using the fields below. The keyword search will search across the name, and summary.

There are 628 matching records. Displaying matches 1 through 20.

Name (Version) Target Authority Last Modified Resources
SUSE Linux Enterprise Server (SLES) 15 STIG for Ansible (Ver 1, Rel 11) SUSE Enterprise Linux 15
Defense Information Systems Agency
10/26/2023 Standalone XCCDF 1.1.4 - SUSE Linux Enterprise Server 15 for Ansible - Ver 1, Rel 11
Cisco IOS Router STIG (Y23M07) Cisco IOS
Defense Information Systems Agency
10/26/2023 SCAP 1.3 Content - Cisco IOS-XE Router NDM STIG Benchmark - Ver 1, Rel 7
SCAP 1.3 Content - Cisco IOS-XE Router RTR STIG Benchmark - Ver 1, Rel 3
Standalone XCCDF 1.1.4 - Cisco IOS XE Router STIG
Standalone XCCDF 1.1.4 - Cisco IOS XR Router STIG
Standalone XCCDF 1.1.4 - Cisco IOS Router STIG
Standalone XCCDF 1.1.4 - Cisco IOS XE Router NDM RTR STIG for Ansible - Ver 2, Rel 3
VMware vRealize Operations 6.x STIG (Y23M10) VMWare vRealize Operations Manager 6.x
Defense Information Systems Agency
10/26/2023 Standalone XCCDF 1.1.4 - Sunset - VMware vRealize Ops 6.x STIG
Standalone XCCDF 1.1.4 - Sunset - VMware vRealize Operations Manager Cassandra STIG - Ver 1, Rel 2
Mozilla Firefox STIG (Version 6, Release 5) Mozilla Firefox
Defense Information Systems Agency
10/26/2023 SCAP 1.2 Content - Mozilla Firefox Linux STIG Benchmark - Ver 6, Rel 4
SCAP 1.2 Content - Mozilla Firefox Windows STIG Benchmark - Ver 6, Rel 5
Automated Content - SCC 5.8 Windows
Automated Content - SCC 5.8 RHEL 6 i686
Automated Content - SCC 5.8 RHEL 6 x86 64
Automated Content - SCC 5.8 RHEL 7/Oracle Linux 7/SLES12/SLES 15 x86 64
Automated Content - SCC 5.8 RHEL 8/Oracle Linux 8 Aarch64
Automated Content - SCC 5.8 RHEL 8/Oracle Linux 8 x86 64
Automated Content - SCC 5.8 RHEL 9x86 64
Standalone XCCDF 1.1.4 - Mozilla Firefox STIG - Ver 6, Rel 5
Apple macOS 13 STIG (Ver 1, Rel 1) Apple macOS 13.0 (Ventura)
Defense Information Systems Agency
10/26/2023 Standalone XCCDF 1.1.4 - Apple macOS 13 (Ventura) STIG - Ver 1, Rel 3
Microsoft IIS 10.0 STIG (Y23M10) Microsoft IIS 10
Defense Information Systems Agency
10/26/2023 Standalone XCCDF 1.1.4 - Microsoft IIS 10.0 STIG
Microsoft IIS 8.5 STIG (Y23M10) IIS 8.5
Defense Information Systems Agency
10/26/2023 Standalone XCCDF 1.1.4 - Sunset - Microsoft IIS 8.5 STIG
Cisco IOS Switch STIG (Y23M07) Cisco IOS
Cisco IOS XE
Cisco NX-OS
Defense Information Systems Agency
10/26/2023 Standalone XCCDF 1.1.4 - Cisco IOS XE Switch STIG
Standalone XCCDF 1.1.4 - Cisco IOS Switch STIG
Standalone XCCDF 1.1.4 - Cisco NX OS Switch STIG
Cisco ASA STIG (Y23M10) Cisco ASA
Defense Information Systems Agency
10/26/2023 Standalone XCCDF 1.1.4 - Cisco ASA STIG
Microsoft Exchange Server 2016 STIG (Y23M10) Microsoft Exchange Server 2016
Defense Information Systems Agency
10/26/2023 Standalone XCCDF 1.1.4 - Microsoft Exchange 2016 STIG
VMWare vRealize Automation 7.x STIG (Y21M10) VMWare vRealize Automation 7.x
Defense Information Systems Agency
10/26/2023 Standalone XCCDF 1.1.4 - Sunset - VMware vRealize Automation 7.x STIG
Red Hat 7 STIG (Ver 3, Rel 13) Red Hat Enterprise Linux 7.0
Defense Information Systems Agency
10/26/2023 SCAP 1.2 Content - Red Hat Enterprise Linux 7 STIG Benchmark - Ver 3, Rel 13
Automated Content - SCC 5.8 RHEL 6 i686
Automated Content - SCC 5.8 RHEL 6 x86 64
Automated Content - SCC 5.8 RHEL 7/Oracle Linux 7/SLES12/SLES 15 x86 64
Automated Content - SCC 5.8 RHEL 8/Oracle Linux 8 Aarch64
Automated Content - SCC 5.8 RHEL 8/Oracle Linux 8 x86 64
Automated Content - SCC 5.8 RHEL 9x86 64
Standalone XCCDF 1.1.4 - Red Hat Enterprise Linux 7 STIG - Ver 3, Rel 13
Standalone XCCDF 1.1.4 - Red Hat Enterprise Linux 7 STIG for Ansible - Ver 3, Rel 13
Standalone XCCDF 1.1.4 - Red Hat Enterprise Linux 7 STIG for Chef - Ver 3, Rel 8
Apple macOS 11 STIG (Ver 1, Rel 8) Apple macOS 11.0 (Big Sur)
Defense Information Systems Agency
10/26/2023 Automated Content - SCC 5.8 Mac OS X x86 64
Standalone XCCDF 1.1.4 - Sunset - Apple macOS 11 (Big Sur) STIG - Ver 1, Rel 8
Red Hat Ansible Automation Controller STIG (Y23M10) Red Hat Ansible Automation Controller
Defense Information Systems Agency
10/26/2023 Standalone XCCDF 1.1.4 - Red Hat Ansible Automation Controller STIG
Microsoft SQL Server 2016 STIG (Y23M10) Microsoft SQL Server 2016
Defense Information Systems Agency
10/26/2023 Standalone XCCDF 1.1.4 - MS SQL Server 2016 STIG
zOS ACF2 STIG (Version 6, Release 58) IBM OS390
Defense Information Systems Agency
10/26/2023 Standalone XCCDF 1.1.4 - IBM zOS STIG
Standalone XCCDF 1.1.4 - z/OS ACF2 Products - Ver 6, Rel 59
Standalone XCCDF 1.1.4 - z/OS SRR Scripts - Ver 6, Rel 59
zOS RACF STIG (Version 6, Release 58) IBM OS390
Defense Information Systems Agency
10/26/2023 Standalone XCCDF 1.1.4 - IBM zOS STIG
Standalone XCCDF 1.1.4 - z/OS RACF Products - Ver 6, Rel 59
SUSE Linux Enterprise Server (SLES) 12 STIG (Ver 2, Rel 11) SUSE Linux Enterprise Server 12.0
Defense Information Systems Agency
10/26/2023 SCAP 1.2 Content - SUSE Linux Enterprise Server 12 STIG Benchmark - Ver 2, Rel 10
Automated Content - SCC 5.8 RHEL 6 i686
Automated Content - SCC 5.8 RHEL 6 x86 64
Automated Content - SCC 5.8 RHEL 7/Oracle Linux 7/SLES12/SLES 15 x86 64
Automated Content - SCC 5.8 RHEL 8/Oracle Linux 8 Aarch64
Automated Content - SCC 5.8 RHEL 8/Oracle Linux 8 x86 64
Automated Content - SCC 5.8 RHEL 9x86 64
Standalone XCCDF 1.1.4 - SUSE Linux Enterprise Server 12 STIG - Ver 2, Rel 12
Kubernetes STIG (Ver 1, Rel 11) Kubernetes
Defense Information Systems Agency
10/26/2023 SCAP 1.2 Content - Kubernetes STIG Benchmark - Ver 1, Rel 3
Standalone XCCDF 1.1.4 - Kubernetes STIG - Ver 1, Rel 11
Apache Tomcat Application Server 9 STIG (Ver 2, Rel 6) Apache Tomcat 9.0
Defense Information Systems Agency
10/26/2023 Standalone XCCDF 1.1.4 - Apache Tomcat Application Server 9 STIG - Ver 2, Rel 6
* This checklist is still undergoing review for inclusion into the NCP.